A position information determination method and device, a server and a storage medium

By using public and private keys to encrypt and decrypt the data in the blockchain system, combined with the target business address information, the problem of servers being unable to accurately determine the location of end users is solved, and more accurate location information determination is achieved.

CN116233225BActive Publication Date: 2026-01-02CHINA UNITED NETWORK COMM GRP CO LTD +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211684677.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-27
Publication Date
2026-01-02
Estimated Expiration
2042-12-27

AI Technical Summary

Technical Problem

In existing technologies, servers cannot accurately determine the location information of end users, which may lead to inaccurate location information.

Method used

By obtaining the user account's account identifier and MDN's location information across multiple time intervals, and using the public and private keys in the blockchain for encryption and decryption, combined with the target business's address information, valid location information is determined and identified as the user account's location information.

Benefits of technology

It improves the accuracy of determining user location information and ensures the validity and consistency of location information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116233225B_ABST
    Figure CN116233225B_ABST
Patent Text Reader

Abstract

The application provides a position information determination method and device, a server and a storage medium, and relates to the technical field of Internet.The method comprises the following steps: obtaining a position determination request; encrypting an account identifier of a user account based on a second public key to generate first encrypted information, and broadcasting the first encrypted information to at least one node; receiving second encrypted information sent by the second node, and decrypting the second encrypted information based on a first private key to obtain service data of the user account when the user account performs a target service in M time intervals; determining effective position information based on multiple time points and an address of the user account when the user account performs the target service at each time point; and determining the position information of the MDN in the M time intervals as the position information of the user account in the case where the position information of the MDN in the M time intervals comprises the effective position information.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of Internet, and in particular to a position information determination method and device, a server and a storage medium. BACKGROUND

[0002] At present, a server can obtain position information of a terminal, and then determine the position information of the terminal as position information of a user using the terminal.

[0003] However, in the above method, since one terminal can be used by multiple users, or one user can use multiple terminals, the manner in which the server determines the position information of a certain terminal as the position information of the user using the terminal can be inaccurate, and can not effectively determine the position information of the user. SUMMARY

[0004] The present application provides a position information determination method and device, a server and a storage medium, which solve the technical problem that the manner in which the server determines the position information of a certain terminal as the position information of the user using the terminal in the related art can be inaccurate, and can not effectively determine the position information of the user.

[0005] In a first aspect, the present application provides a position information determination method, comprising: obtaining a position determination request, the position determination request comprising an account identifier of a user account, a mobile directory number (MDN) corresponding to the user account, and position information of the MDN in M time intervals, the position determination request being used to request to determine position information of the user account, M being an integer greater than or equal to 1; performing encryption processing on the account identifier of the user account based on a second public key to generate first encrypted information, and broadcasting the first encrypted information to at least one node, the second public key being a public key included in a second node, the second node being one of the at least one node, the first node and the at least one node belonging to the same blockchain; receiving second encrypted information sent by the second node, and performing decryption processing on the second encrypted information based on a first private key to obtain service data of the user account when performing a target service in the M time intervals, the service data comprising a plurality of time instants and an address of the user account when performing the target service at each time instant in the plurality of time instants, the target service being used to verify the identity of the user account, the first private key being a private key included in the first node; determining valid position information based on the plurality of time instants and the address of the user account when performing the target service at each time instant; and determining, in a case where the position information of the MDN in the M time intervals comprises the valid position information, the position information of the MDN in the M time intervals as the position information of the user account.

[0006] Optionally, the plurality of time points comprises a first time point, and the valid location information is determined based on the plurality of time points and addresses of the user account at each time point for the target service, specifically comprising: determining a network device corresponding to the first time point and a first address, the first address being an address of the user account at the first time point for the target service, the network device being configured to provide services for a terminal corresponding to the user account; and determining that the valid location information comprises location information of the network device.

[0007] Optionally, the location information determination method further comprises: generating a first digest based on the first encrypted information; performing encryption processing on the first digest based on the first private key to generate a first private key signature; and broadcasting the first private key signature to the at least one node.

[0008] Optionally, the location information determination method further comprises: receiving a second private key signature sent by the second node; performing decryption processing on the second private key signature based on the second public key to obtain a third digest; and generating a fourth digest based on the second encrypted information; and the decryption processing on the second encrypted information based on the first private key to obtain the service data of the user account in the M time intervals for the target service, specifically comprising: in the case that the fourth digest is the same as the third digest, performing decryption processing on the second encrypted information based on the first private key to obtain the service data of the user account in the M time intervals for the target service.

[0009] In a second aspect, the present application provides a location information determination method, comprising: receiving first encrypted information sent by a first node, and performing decryption processing on the first encrypted information based on a second private key to obtain an account identifier of a user account, the second private key being a private key included in the second node; determining service data of the user account in M time intervals for a target service based on the account identifier of the user account, the service data comprising a plurality of time points and addresses of the user account at each time point in the plurality of time points for the target service, the target service being configured to verify the identity of the user account, M being an integer greater than or equal to 1; performing encryption processing on the service data of the user account in the M time intervals for the target service based on a first public key to generate second encrypted information, and broadcasting the second encrypted information to the first node and other nodes, the other nodes being at least one node except the second node, the first node and the at least one node belonging to the same blockchain.

[0010] Optionally, the position information determination method further includes: receiving a first private key signature sent by the first node; decrypting the first private key signature based on the first public key to obtain a first digest; and generating a second digest based on the first encrypted information; and the decrypting the first encrypted information based on the second private key to obtain the account identifier of the user account specifically includes: in a case where the second digest is the same as the first digest, decrypting the first encrypted information based on the second private key to obtain the account identifier of the user account.

[0011] Optionally, the position information determination method further includes: generating a third digest based on the second encrypted information; encrypting the third digest based on the second private key to generate a second private key signature; and broadcasting the second private key signature to the first node and the other nodes.

[0012] In a third aspect, the present application provides a position information determination device, comprising: an obtaining module, a processing module, a receiving module and a determining module; the obtaining module is used for obtaining a position determination request, the position determination request comprising an account identifier of a user account, an MDN corresponding to the user account and position information of the MDN in M time intervals, the position determination request being used for requesting to determine the position information of the user account, M being an integer greater than or equal to 1; the processing module is used for encrypting the account identifier of the user account based on a second public key to generate first encrypted information, and broadcasting the first encrypted information to at least one node, the second public key being a public key included in a second node, the second node being one of the at least one node, the first node and the at least one node belonging to the same blockchain; the receiving module is used for receiving second encrypted information sent by the second node, and decrypting the second encrypted information based on a first private key to obtain service data of the user account when performing a target service in the M time intervals, the service data comprising a plurality of time points and an address of the user account performing the target service at each time point in the plurality of time points, the target service being used for verifying the identity of the user account, the first private key being a private key included in the first node; the determining module is used for determining valid position information based on the plurality of time points and the address of the user account performing the target service at the each time point; and the determining module is further used for determining the position information of the MDN in the M time intervals as the position information of the user account in a case where the position information of the MDN in the M time intervals comprises the valid position information.

[0013] Optionally, the plurality of time points comprises a first time point, the determining module is specifically configured to determine a network device corresponding to the first time point and a first address, the first address being an address of the user account performing the target service at the first time point, and the network device being configured to provide service for a terminal corresponding to the user account; and the determining module is specifically configured to determine position information of the network device in the valid position information.

[0014] Optionally, the processing module is further configured to generate a first digest based on the first encrypted information, and to perform encryption processing on the first digest based on the first private key to generate a first private key signature; and the processing module is further configured to broadcast the first private key signature to the at least one node.

[0015] Optionally, the receiving module is further configured to receive a second private key signature sent by the second node; the processing module is further configured to perform decryption processing on the second private key signature based on the second public key to obtain a third digest, and to generate a fourth digest based on the second encrypted information; and the processing module is specifically further configured to, in a case where the fourth digest is the same as the third digest, perform decryption processing on the second encrypted information based on the first private key to obtain the service data of the user account performing the target service in the M time intervals.

[0016] In a fourth aspect, the present application provides a position information determination apparatus, comprising a receiving module, a determining module and a processing module; the receiving module is configured to receive first encrypted information sent by a first node, and to perform decryption processing on the first encrypted information based on a second private key to obtain an account identifier of a user account, the second private key being a private key included in the second node; the determining module is configured to determine service data of the user account performing a target service in M time intervals based on the account identifier of the user account, the service data comprising a plurality of time points and an address of the user account performing the target service at each time point in the plurality of time points, the target service being configured to verify the identity of the user account, and M being an integer greater than or equal to 1; and the processing module is configured to perform encryption processing on the service data of the user account performing the target service in the M time intervals based on a first public key to generate second encrypted information, and to broadcast the second encrypted information to the first node and other nodes, the other nodes being at least one node excluding the second node, and the first node and the at least one node belonging to the same blockchain.

[0017] Optionally, the receiving module is further configured to receive a first private key signature sent by the first node; the processing module is further configured to decrypt the first private key signature based on the first public key to obtain a first digest; and generate a second digest based on the first encrypted information; and the processing module is specifically configured to, in a case where the second digest is the same as the first digest, decrypt the first encrypted information based on the second private key to obtain the account identifier of the user account.

[0018] Optionally, the processing module is further configured to generate a third digest based on the second encrypted information; the processing module is further configured to encrypt the third digest based on the second private key to generate a second private key signature; and the processing module is further configured to broadcast the second private key signature to the first node and the other nodes.

[0019] In a fifth aspect, the present application provides a server, comprising: a processor and a memory configured to store processor-executable instructions; wherein the processor is configured to execute the instructions to implement any of the optional location information determination methods in the first aspect, or implement any of the optional location information determination methods in the second aspect.

[0020] In a sixth aspect, the present application provides a computer-readable storage medium, and the computer-readable storage medium stores instructions, when the instructions in the computer-readable storage medium are executed by a server, the server can execute any of the optional location information determination methods in the first aspect, or execute any of the optional location information determination methods in the second aspect.

[0021] The application provides a position information determination method, device, server and storage medium, in the embodiment of the application, a first node can obtain a position determination request, the position determination request comprises an account identifier of a user account, MDN corresponding to the user account and position information of the MDN in M time intervals, then the first node can perform encryption processing on the account identifier of the user account based on a second public key, generate first encryption information, and broadcast the first encryption information to at least one node, after receiving second encryption information sent by a second node, the first node can perform decryption processing on the second encryption information based on a first private key, obtain service data of the user account when performing a target service in the M time intervals, the service data comprises a plurality of time points and an address of the user account when performing the target service at each time point in the plurality of time points, then the first node can determine effective position information based on the plurality of time points and the address of the user account when performing the target service at each time point, in the case that the position information of the MDN in the M time intervals comprises the effective position information, it is indicated that the position information of the MDN in the M time intervals comprises position information of the user account, at this time, the first node can determine that the position information of the MDN in the M time intervals is the position information of the user account. In the application, since the target service is used to verify the identity of the user account, the first node can determine the effective position information based on the plurality of time points and the address of the user account when performing the target service at each time point in the plurality of time points, since the effective position information is the position information of the user account, in the case that the position information of the MDN in the M time intervals comprises the position information of the user account, the first node determines the position information of the MDN in the M time intervals as the position information of the user account, which can improve the accuracy of determining the position information of the user account. BRIEF DESCRIPTION OF DRAWINGS

[0022] In order to more clearly illustrate the technical solutions in the embodiments of the application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description.

[0023] Figure 1 A network architecture schematic diagram of a blockchain system provided by the embodiments of the application is provided.

[0024] Figure 2 A flowchart of a position information determination method provided by the embodiments of the application is provided.

[0025] Figure 3 A flowchart of another position information determination method provided by the embodiments of the application is provided.

[0026] Figure 4 A flowchart of another position information determination method provided by the embodiments of the application is provided.

[0027] Figure 5 A flowchart of another position information determination method provided by an embodiment of the present application is shown in FIG. 2.

[0028] Figure 6 A structure diagram of a position information determination device provided by an embodiment of the present application is shown in FIG. 3.

[0029] Figure 7 A structure diagram of another position information determination device provided by an embodiment of the present application is shown in FIG. 4.

[0030] Figure 8 A structure diagram of another position information determination device provided by an embodiment of the present application is shown in FIG. 5.

[0031] Figure 9 A structure diagram of another position information determination device provided by an embodiment of the present application is shown in FIG. 6. DETAILED DESCRIPTION

[0032] The position information determination method, device, server and storage medium provided by an embodiment of the present application will be described in detail below with reference to the accompanying drawings.

[0033] The terms "first" and "second" and the like in the description of the present application and the accompanying drawings are used to distinguish different objects, rather than to describe a specific order of the objects, for example, the first node and the second node are used to distinguish different nodes, rather than to describe a specific order of the nodes.

[0034] In addition, the terms "include" and "have" and any variations thereof mentioned in the description of the present application are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units is not limited to the listed steps or units, but can optionally include other steps or units not listed or can optionally include other steps or units inherent to the process, method, product or device.

[0035] It should be noted that in the embodiments of the present application, the words "exemplary" or "for example" are used to mean serving as an example, instance, or illustration. Any embodiment or design presented as "exemplary" or "for example" in the embodiments of the present application should not be interpreted as being more preferred or advantageous than other embodiments or design solutions. Rather, the use of "exemplary" or "for example" is intended to present concepts in a concrete manner.

[0036] In the present application, "and / or" includes using any one of the two methods or using both methods.

[0037] In the description of the present application, "a plurality of" means two or more, unless otherwise specified.

[0038] The following explains some concepts involved in the location information determination method, apparatus, server, and storage medium provided in the embodiments of the present invention.

[0039] As described in the background art, in related technologies, the method by which a server determines the location information of a terminal as the location information of a user using that terminal may be inaccurate and may fail to effectively determine the user's location information. Therefore, this invention provides a location information determination method, apparatus, server, and storage medium. Since the target service is used to verify the identity of the user account, the first node can determine the address of the target service as valid location information based on the multiple time points and the user account's address at each of those multiple time points. Because this valid location information is the user account's location information, when the location information of the MDN in M ​​time intervals includes the user account's location information, the first node can improve the accuracy of determining the user account's location information by determining the MDN's location information in those M time intervals as the user account's location information.

[0040] The location information determination method, apparatus, server, and storage medium provided in this invention can be applied to blockchain systems, such as... Figure 1 As shown, the blockchain system may include node 101, node 102, and node 103. Typically, in practical applications, the connections between these devices or service functions can be wireless. To easily and intuitively illustrate the connection relationships between the devices, Figure 1 The diagram uses solid lines to illustrate that each node in this blockchain system can broadcast encrypted information to other nodes.

[0041] Optionally, in this embodiment of the invention, nodes 101, 102, and 103 can be independent devices, servers integrated with blockchain node functionality, or cloud servers providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery network (CDN), and big data and artificial intelligence platforms. In this embodiment of the invention, node 101 can be a first node or a second node; this embodiment of the invention does not limit the number of nodes in the blockchain system.

[0042] The position information determination method, device, server and storage medium provided by the embodiments of the present application are applied to the application scenario of position information determination. When a first node obtains an identifier of a user account, corresponding MDN of the user account, and position information of the MDN in M time intervals, the identifier of the user account can be encrypted based on a second public key to generate first encrypted information, and then the first encrypted information is broadcast to at least one node. After the first node receives the second encrypted information sent by the second node, the second encrypted information can be decrypted based on a first private key to obtain service data of the user account when performing a target service in the M time intervals, and then based on a plurality of time points and an address of the user account when performing the target service at each time point in the plurality of time points, effective position information is determined. When the position information of the MDN in the M time intervals includes the effective position information, the position information of the MDN in the M time intervals is determined as the position information of the user account.

[0043] In combination with the above Figure 1 The position information determination method provided by the embodiments of the present application is described in detail from the perspective of interaction between devices in the blockchain system, to explain the process of determining service data of a user account when performing a target service in M time intervals based on an identifier of the user account by a second node, and determining effective position information based on a plurality of time points and an address of the user account when performing the target service at each time point in the plurality of time points by the first node.

[0044] As Figure 2 The position information determination method provided by the embodiments of the present application can include S101-S108.

[0045] S101, a first node obtains a position determination request.

[0046] The position determination request includes an account identifier of the user account, an MDN corresponding to the user account, and position information of the MDN in M time intervals. The position determination request is used to request to determine the position information of the user account, and M is an integer greater than or equal to 1.

[0047] It can be understood that the identifier of the user account is used to identify the identity of the user account, for example, the identifier of the user account can be the identity card number of the user account, the passport number of the user account, or the name of the user account.

[0048] It should be understood that the position information corresponding to the MDN in the last M time intervals can also be understood as the position information of the position reached (or passed) by the terminal device corresponding to the MDN when carrying (or using) the MDN in the last M time intervals.

[0049] It can be understood that the terminal device corresponding to the MDN can be a terminal device used by the user account or a terminal device used by the other user, and the location determination request is used to request to determine whether the location information of the MDN in the M time intervals is the location information of the user account in the M time intervals.

[0050] Optionally, one time interval can be one day, the M can be 14, the first node can query the MDN corresponding to the user account, and the location information of the location reached by the user account carrying the MDN in the 14 days.

[0051] Optionally, the first node can be a node of a railway system.

[0052] Optionally, the first node can accept a location determination request sent by a terminal or a location determination request sent by another node, such as a location determination request sent by an operator node.

[0053] S102, the first node encrypts the account identifier of the user account based on the second public key, generates first encrypted information, and broadcasts the first encrypted information to at least one node.

[0054] The second public key is a public key included in the second node, the second node is one of the at least one node, and the first node and the at least one node belong to the same blockchain.

[0055] It can be understood that the second node includes a second public key and a second private key, and when the first node uses the second public key to encrypt certain information and broadcasts it to the blockchain system, the second node can decrypt the certain information based on the second private key and obtain the certain information.

[0056] It can be understood that the first node can send the first encrypted information to the blockchain in the form of a broadcast message, so that at least one node in the blockchain can obtain the first encrypted information.

[0057] Optionally, the first node can store a first algorithm, which is an algorithm agreed upon in advance by the first node and the second node, and when the first node needs to send information to the second node, the first node can use the second public key and the first algorithm to encrypt the to-be-sent information to obtain the encrypted information.

[0058] Optionally, the second node can be a node of a bank system.

[0059] Optionally, the first node and the at least one node can also belong to the same alliance chain.

[0060] In an optional implementation, the first node can further send a data acquisition request to the second node, the data acquisition request including the first encrypted data, the data acquisition request being used to request to acquire service data of the user account in M time intervals.

[0061] S103, the second node receives the first encrypted information sent by the first node, and decrypts the first encrypted information based on a second private key to obtain an account identifier of the user account.

[0062] The second private key is a private key included in the second node.

[0063] Optionally, the second node also stores a first algorithm, and the second node can decrypt the first encrypted information sent by the first node based on the second algorithm and the second public key.

[0064] S104, the second node determines service data of the user account when performing a target service in M time intervals based on the account identifier of the user account.

[0065] The service data includes a plurality of time points and an address of the user account when performing the target service at each time point in the plurality of time points, the target service being used to verify the identity of the user account, and M is an integer greater than or equal to 1.

[0066] It should be understood that, since the target service is used to verify the identity of the user account, when the user account performs the target service, it indicates that the user account is using a terminal device corresponding to the user account at this time, and at this time, the location information of the terminal device corresponding to the user account is the location information of the user account.

[0067] Optionally, the target service can be a payment type service, and the target service includes face verification information of the user account.

[0068] It can be understood that the service data of the target service can also be understood as full packet information of the user account when performing the target service, and the full packet information includes a time point, a source address and a destination address of the full packet information, and the source address is an IP address of the terminal device corresponding to the user account.

[0069] It should be understood that the user account can perform the target service multiple times in the M time intervals, and the service data of the target service can be a plurality of full packet information, wherein each full packet information includes a time point, a source address and a destination address.

[0070] S105, the second node encrypts the service data of the user account when performing the target service in the M time intervals based on the first public key, generates second encrypted information, and broadcasts the second encrypted information to the first node and other nodes.

[0071] The other nodes are at least one node other than the second node in the at least one node, and the first node and the at least one node belong to the same blockchain.

[0072] It should be understood that the first public key is a public key included in the first node.

[0073] It can be understood that the second node sends the second encrypted information to the blockchain in the form of a broadcast message, so that at least one node in the blockchain can obtain the second encrypted information.

[0074] S106, the first node receives the second encrypted information sent by the second node, and decrypts the second encrypted information based on the first private key to obtain the service data of the user account when performing the target service in the M time intervals.

[0075] The service data includes a plurality of time points and an address of the user account performing the target service at each time point in the plurality of time points, and the target service is used to verify the identity of the user account, and the first private key is a private key included in the first node.

[0076] It can be understood that the first private key is a private key corresponding to the first public key, because the second node encrypts the service data of the user account when performing the target service in the M time intervals based on the first public key to obtain the second encrypted information, and the first public key is a public key included in the first node, so the first node can decrypt the second encrypted information based on the first private key to obtain the service data of the user account when performing the target service in the M time intervals.

[0077] S107, the first node determines valid location information based on the plurality of time points and the address of the user account performing the target service at each time point.

[0078] With the above description of the embodiments, it should be understood that, since the target service is used to verify the identity of the user account, when the user account performs the target service, it indicates that the user account is currently using the terminal device corresponding to the user account, at this time, the first node can determine the location information of the terminal device corresponding to the user account as the location information of the user account, and since the address of the service user account performing the target service at each time includes a source address and a destination address, the source address is the address of the terminal device corresponding to the user account, therefore, the first node can determine the effective location information based on the plurality of times and the address of the user account performing the target service at each time.

[0079] In a case where the location information of the MDN in the M time intervals includes the effective location information, the first node determines the location information of the MDN in the M time intervals as the location information of the user account.

[0080] It can be understood that, in a case where the location information of the MDN in the M time intervals includes the effective location, it indicates that the location information of the MDN in the M time intervals includes the location information of the user account, at this time, the first node can determine the location information of the MDN in the M time intervals as the location information of the user account carrying the MDN in the M time intervals, and determine the location information of the MDN in the M time intervals as the location information of the user account.

[0081] It should be noted that, in a case where the location information of the MDN at the first time is the same as the location information of the user account at the second time, it indicates that the location information of the MDN in the M time intervals includes the location information of the user account at the second time, wherein the first time and the second time are times in the M time intervals, and the time difference between the first time and the second time is less than or equal to a time difference threshold.

[0082] Optionally, the time difference threshold can be 1 hour.

[0083] In an implementation manner of the embodiment of the application, the location information of the MDN in the M time intervals can be Beijing, and the effective location information can be a latitude and longitude information, when the Beijing includes the latitude and longitude information, the first node can determine that the location information of the MDN in the M time intervals includes the effective location information.

[0084] In an implementation manner of the embodiment of the application, the location determination request can include a plurality of MDNs and the location information of each MDN in the M time intervals, that is, the user account corresponds to a plurality of MDNs, at this time, the first node can determine whether the location information of each MDN in the M time intervals includes the effective location information.

[0085] In the embodiment of the present application, the first node can obtain a location determination request, the location determination request comprising an account identifier of a user account, a MDN corresponding to the user account, and location information of the MDN in M time intervals, then encrypt the account identifier of the user account based on a second public key to generate first encrypted information, and broadcast the first encrypted information to at least one node. After receiving the second encrypted information sent by the second node, the first node can decrypt the second encrypted information based on a first private key to obtain service data of the user account when performing a target service in the M time intervals, the service data comprising a plurality of time points and an address of the user account performing the target service at each time point in the plurality of time points. Then, the first node can determine valid location information based on the plurality of time points and the address of the user account performing the target service at each time point, and in the case that the location information of the MDN in the M time intervals comprises the valid location information, it is indicated that the location information of the MDN in the M time intervals comprises the location information of the user account. At this time, the first node can determine the location information of the MDN in the M time intervals as the location information of the user account. In the present application, since the target service is used to verify the identity of the user account, the first node can determine the valid location information based on the plurality of time points and the address of the user account performing the target service at each time point in the plurality of time points. Since the valid location information is the location information of the user account, in the case that the location information of the MDN in the M time intervals comprises the location information of the user account, the first node determines the location information of the MDN in the M time intervals as the location information of the user account, which can improve the accuracy of determining the location information of the user account.

[0086] In an implementation manner of the embodiment of the present application, the plurality of time points comprises a first time point, and the first node determines the valid location information based on the first time point and the address of the user account performing the target service at the first time point. Figure 2 As shown in S1011-S1012, the first node can obtain the location determination request, and the location determination request can comprise the account identifier of the user account, the MDN corresponding to the user account, and the location information of the MDN in the M time intervals. Figure 3 As shown in S1011-S1012, the first node can obtain the location determination request, and the location determination request can comprise the account identifier of the user account, the MDN corresponding to the user account, and the location information of the MDN in the M time intervals.

[0087] S1071, the first node determines a network device corresponding to the first time point and the first address.

[0088] The first address is the address of the user account performing the target service at the first time point, and the network device is used to provide services for a terminal corresponding to the user account.

[0089] It can be understood that the address of the target service performed by the user account at the first moment can also be understood as routing information of the target service, and the network device is an access network device used by the user account to perform the target service at the first moment, and the network device is configured to provide network services for a terminal corresponding to the user account.

[0090] Optionally, the network device can be a base station or a router. Specifically, when the user account uses a 4G or 5G network to perform the target service at the first moment, the network device is a base station configured to provide network services for the terminal, and when the user account uses a wireless network to perform the target service at the first moment, the network device is a router.

[0091] It should be understood that the first address is an IP address, and the first node can store information of a terminal device corresponding to the IP address at each moment in the M time intervals. The first node can determine the terminal device of the user account and the identifier of the access network device connected by the terminal device at the first moment based on the first moment and the first address.

[0092] S1072, the first node determines that the valid position information includes the position information of the network device.

[0093] In the embodiment of the application, the first node stores the latitude and longitude information of each base station of a plurality of base stations and the position information of each router of a plurality of routers. The first node can determine the position information of the network device based on the identifier of the network device, and determine the position information of the network device as the position information of the user account at the first moment.

[0094] It can be understood that the valid position information is position information that has been reached by the user account in the M time intervals. The valid position information can include a plurality of position information, and the first node can determine that the position information of the network device is included in the valid position information.

[0095] It can be understood that the first node can determine the position information of a plurality of network devices based on the service data, and then determine the position information of the plurality of network devices as the valid position information.

[0096] In combination Figure 2 As Figure 4 shown, the position information determination method provided by the embodiment of the application further includes S109-S113.

[0097] S109, the first node generates a first digest based on the first encrypted information.

[0098] It can be understood that the first node can generate the first digest based on the digest algorithm and the first encrypted information.

[0099] It should be understood that the digest algorithm is a digest algorithm agreed in advance with the second node.

[0100] S110, the first node encrypts the first digest based on the first private key to generate a first private key signature.

[0101] It can be understood that since the first encrypted information is generated by the first node based on the second public key, the second node can decrypt the first encrypted information based on the second public key, and cannot determine that the first encrypted information is the first encrypted information sent by the first node. At this time, the first node can encrypt the first digest based on the first private key to generate a first private key signature.

[0102] It should be understood that the first private key signature can also be understood as the signature of the first node, and the second node can decrypt the first private key signature based on the first public key to determine that the first private key signature is the signature of the first node.

[0103] S111, the first node broadcasts the first private key signature to at least one node.

[0104] S112, the second node receives the first private key signature sent by the first node.

[0105] S113, the second node decrypts the first private key signature based on the first public key to obtain the first digest, and generates a second digest based on the first encrypted information.

[0106] It can be understood that the second node decrypts the first private key signature based on the first public key to obtain the first digest, which indicates that the first digest is the digest sent by the first node, and the second node successfully authenticates the identity of the first node.

[0107] In combination with the description of the above embodiment, the first node broadcasts the first encrypted information to the at least one node, and it should be understood that the second node can also obtain the first encrypted information, and generate a second digest based on the first encrypted information and the digest algorithm.

[0108] Continue as Figure 4 shown, the second node decrypts the first encrypted information based on the second private key to obtain the account identifier of the user account, specifically including S1031.

[0109] S1031, in the case that the second digest is the same as the first digest, decrypting the first encrypted information based on the second private key to obtain the account identifier of the user account.

[0110] It should be understood that if the second digest is the same as the first digest, it means that the first encrypted information is encrypted information sent by the first node. In this case, the second node can decrypt the first encrypted information based on the second private key to obtain the user account's account identifier.

[0111] In this embodiment of the invention, the first node encrypts the account identifier of the user account based on the second public key to obtain first encrypted information, and encrypts the first digest based on the first private key. It can be determined that the second node can encrypt the first digest based on the first public key to determine that the first digest is the digest of the first node. The second node generates a second digest based on the first encrypted information, which can be determined that the first encrypted information is the encrypted information sent by the second node, thus ensuring the security of the encrypted information transmission.

[0112] Combination Figure 2 ,like Figure 5 As shown, the location information determination method provided in this embodiment of the invention further includes S114-S118.

[0113] S114. The second node generates a third digest based on the second encrypted information.

[0114] Understandably, the second node can generate a third digest based on a pre-agreed digest algorithm and the first encrypted information.

[0115] S115. The second node encrypts the third digest based on the second private key to generate a second private key signature.

[0116] It should be understood that the second private key signature can also be understood as the signature of the second node. The first node can decrypt the second private key signature based on the second public key to determine that the second private key signature is the signature of the second node.

[0117] S116, The second node broadcasts the second private key signature to the first node and other nodes.

[0118] It should be understood that the other node is any node other than the second node among the at least one nodes.

[0119] S117. The first node receives the second private key signature sent by the second node.

[0120] S118. The first node decrypts the signature of the second private key based on the second public key to obtain the third digest; and generates the fourth digest based on the second encrypted information.

[0121] It can be understood that the first node decrypts the second private key signature based on the second public key to obtain the third digest, which indicates that the third digest is the digest sent by the second node, and the first node successfully authenticates the second node.

[0122] In combination with the description of the above embodiments, the second node broadcasts the second encrypted information to the other node, and it should be understood that the first node can also obtain the second encrypted information, and generate a fourth digest based on the second encrypted information and the digest algorithm.

[0123] As shown in Figure 5 , the first node decrypts the second encrypted information based on the first private key to obtain the service data of the user account when performing the target service in the M time intervals, specifically including S1061.

[0124] S1061, in the case that the fourth digest is the same as the third digest, the first node decrypts the second encrypted information based on the first private key to obtain the service data of the user account when performing the target service in the M time intervals.

[0125] It should be understood that in the case that the fourth digest is the same as the third digest, it indicates that the second encrypted information is the encrypted information sent by the second node, and at this time, the first node can decrypt the first encrypted information based on the first private key to obtain the service data of the user account when performing the target service in the M time intervals.

[0126] The embodiments of the present application can divide the function modules of the server according to the above method examples, for example, each function module can be divided according to each function, or two or more functions can be integrated in one processing module. The above integrated module can be realized in the form of hardware or in the form of software function module. It should be noted that the division of the modules in the embodiments of the present application is illustrative, and is only a logical function division, and another division mode can be used in actual implementation.

[0127] In the case of dividing each function module according to each function, Figure 6 a possible structure schematic diagram of the position information determination device involved in the above embodiments is shown, as Figure 6 shown, the position information determination device 20 can include an acquisition module 201, a processing module 202, a receiving module 203, and a determination module 204.

[0128] The acquisition module 201 is configured to acquire a location determination request, the location determination request comprising an account identifier of the user account, a MDN corresponding to the user account, and location information of the MDN in M time intervals, the location determination request being used to request to determine the location information of the user account, M being an integer greater than or equal to 1.

[0129] The processing module 202 is configured to perform encryption processing on the account identifier of the user account based on a second public key, to generate first encryption information, and to broadcast the first encryption information to at least one node, the second public key being a public key included in a second node, the second node being one of the at least one node, and the first node and the at least one node belonging to the same blockchain.

[0130] The receiving module 203 is configured to receive second encryption information sent by the second node, and to perform decryption processing on the second encryption information based on a first private key to obtain service data of the user account when performing a target service in the M time intervals, the service data comprising a plurality of time points and an address of the user account performing the target service at each time point in the plurality of time points, the target service being used to verify the identity of the user account, and the first private key being a private key included in the first node.

[0131] The determination module 204 is configured to determine valid location information based on the plurality of time points and the address of the user account performing the target service at each time point.

[0132] The determination module 204 is further configured to determine the location information of the MDN in the M time intervals as the location information of the user account in a case where the location information of the MDN in the M time intervals comprises the valid location information.

[0133] Optionally, the plurality of time points comprises a first time point.

[0134] The determination module 204 is specifically configured to determine a network device corresponding to the first time point and a first address, the first address being the address of the user account performing the target service at the first time point, and the network device being used to provide services for a terminal corresponding to the user account.

[0135] The determination module 204 is specifically configured to determine that the network device comprises location information in the valid location information.

[0136] Optionally, the processing module 202 is further configured to generate a first digest based on the first encryption information.

[0137] The processing module 202 is further configured to perform encryption processing on the first digest based on the first private key to generate a first private key signature.

[0138] The processing module 202 is further configured to broadcast the first private key signature to the at least one node.

[0139] Optionally, the receiving module 203 is further configured to receive the second private key signature sent by the second node.

[0140] The processing module 202 is further configured to decrypt the second private key signature based on the second public key to obtain a third digest, and generate a fourth digest based on the second encrypted information.

[0141] The processing module 202 is further configured to, in a case where the fourth digest is the same as the third digest, decrypt the second encrypted information based on the first private key to obtain the service data of the user account when performing the target service in the M time intervals.

[0142] In the case of using an integrated unit, Figure 7 A possible structural diagram of the position information determination apparatus involved in the above embodiments is shown. As shown in Figure 7 The position information determination apparatus 30 can include a processing module 301 and a communication module 302. The processing module 301 can be configured to control and manage the actions of the position information determination apparatus 30. The communication module 302 can be configured to support the communication of the position information determination apparatus 30 with other entities. Optionally, as shown in Figure 7 The position information determination apparatus 30 can further include a storage module 303 configured to store the program code and data of the position information determination apparatus 30.

[0143] The processing module 301 can be a processor or a controller. The communication module 302 can be a transceiver, a transceiver circuit, or a communication interface, etc. The storage module 303 can be a memory.

[0144] When the processing module 301 is a processor, the communication module 302 is a transceiver, and the storage module 303 is a memory, the processor, the transceiver, and the memory can be connected through a bus. The bus can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc.

[0145] In the case of dividing each functional module corresponding to each function, Figure 8 A possible structural diagram of the position information determination apparatus involved in the above embodiments is shown. As shown in Figure 8As shown, the position information determination apparatus 40 can comprise a receiving module 401, a determination module 402 and a processing module 403.

[0146] The receiving module 401 is configured to receive the first encrypted information sent by the first node, and decrypt the first encrypted information based on a second private key to obtain the account identifier of the user account, the second private key being a private key included in the second node.

[0147] The determination module 402 is configured to determine, based on the account identifier of the user account, the service data of the user account when performing a target service in M time intervals, the service data comprising a plurality of time points and an address of the user account when performing the target service at each time point in the plurality of time points, the target service being used to verify the identity of the user account, M being an integer greater than or equal to 1.

[0148] The processing module 403 is configured to encrypt the service data of the user account when performing the target service in M time intervals based on a first public key, generate second encrypted information, and broadcast the second encrypted information to the first node and other nodes, the other nodes being at least one node other than the second node, the first node and the at least one node belonging to the same blockchain.

[0149] Optionally, the receiving module 401 is further configured to receive a first private key signature sent by the first node.

[0150] The processing module 403 is further configured to decrypt the first private key signature based on the first public key to obtain a first digest, and generate a second digest based on the first encrypted information.

[0151] The processing module 403 is specifically configured to, in a case where the second digest is the same as the first digest, decrypt the first encrypted information based on the second private key to obtain the account identifier of the user account.

[0152] Optionally, the processing module 403 is further configured to generate a third digest based on the second encrypted information.

[0153] The processing module 403 is further configured to encrypt the third digest based on the second private key to generate a second private key signature.

[0154] The processing module 403 is further configured to broadcast the second private key signature to the first node and the other nodes.

[0155] In the case of using an integrated unit, Figure 9 A possible structural schematic diagram of the position information determination apparatus involved in the above embodiments is shown. As shown in Figure 9As shown, the position information determination apparatus 50 can include a processing module 501 and a communication module 502. The processing module 501 can be configured to control and manage the actions of the position information determination apparatus 50. The communication module 502 can be configured to support the communication of the position information determination apparatus 50 with other entities. Optionally, as shown, the position information determination apparatus 50 can further include a storage module 503 configured to store the program codes and data of the position information determination apparatus 50. Figure 9

[0156] The processing module 501 can be a processor or a controller. The communication module 502 can be a transceiver, a transceiving circuit, a communication interface, or the like. The storage module 503 can be a memory.

[0157] When the processing module 501 is a processor, the communication module 502 is a transceiver, and the storage module 503 is a memory, the processor, the transceiver, and the memory can be connected through a bus. The bus can be a peripheral component interconnect (PCI) bus, an extended industry standard architecture (EISA) bus, or the like. The bus can be divided into an address bus, a data bus, a control bus, or the like.

[0158] It should be understood that the size of the sequence number of each process described above does not mean the order of execution, and the execution order of each process should be determined according to its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0159] Those skilled in the art can realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be realized by electronic hardware or a combination of computer software and electronic hardware. Whether the functions are realized in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.

[0160] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the above-described system, apparatus, and unit can refer to the corresponding processes in the foregoing method embodiments, which will not be described here.

[0161] ​The units described as separate components may or may not be physically separate, and the components displayed as units may or may not be physical units, i.e. may be located in one place, or may be distributed on multiple network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment scheme.

[0162] In the above embodiments, all or part can be realized by software, hardware, firmware or any combination thereof. When realized by software, all or part can be realized in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network or other programmable devices. The computer instructions can be stored in a computer readable storage medium or transferred from one computer readable storage medium to another, for example, the computer instructions can be transferred from one website, computer, server or data center to another website, computer, server or data center through wired (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.) mode. The computer readable storage medium can be any available medium that can be accessed by a computer or data storage device including one or more servers, data centers, etc. integrated with one or more media. The available medium can be a magnetic medium (such as a floppy disk, a hard disk, a magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid state disk (SSD)) and the like.

[0163] The above is only a specific embodiment of the present application, but the protection scope of the present application is not limited thereto, any person skilled in the art can easily think of changes or replacements within the technical range disclosed by the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A method for determining location information, characterized in that, Applied to the first node, the method includes: A location determination request is obtained, wherein the location determination request includes the user account's account identifier, the mobile subscriber number (MDN) corresponding to the user account, and the location information of the MDN in M ​​time intervals. The location determination request is used to request the determination of the location information of the user account, where M is an integer greater than or equal to 1. The user account identifier is encrypted based on the second public key to generate first encrypted information, and the first encrypted information is broadcast to at least one node. The second public key is a public key included in the second node, the second node is one of the at least one nodes, and the first node and the at least one node belong to the same blockchain. The system receives the second encrypted information sent by the second node and decrypts the second encrypted information based on the first private key to obtain the service data of the user account when performing the target service in the M time intervals. The service data includes multiple time intervals and the address of the user account when performing the target service in each of the multiple time intervals. The target service is used to verify the identity of the user account. The first private key is the private key included in the first node. Based on the multiple times and the address where the user account performs the target service at each time, determine the valid location information; If the location information of the MDN in the M time intervals includes the valid location information, the location information of the MDN in the M time intervals shall be determined as the location information of the user account.

2. The location information determination method according to claim 1, characterized in that, The plurality of times includes a first time. The determination of valid location information based on the plurality of times and the address of the user account performing the target service at each time includes: A network device is identified that corresponds to both the first time point and the first address, where the first address is the address where the user account performs the target service at the first time point, and the network device is used to provide services to the terminal corresponding to the user account. The valid location information includes the location information of the network device.

3. The location information determination method according to claim 1, characterized in that, The method further includes: Based on the first encrypted information, a first digest is generated; The first digest is encrypted based on the first private key to generate a first private key signature. Broadcast the first private key signature to at least one node.

4. The location information determination method according to any one of claims 1-3, characterized in that, The method further includes: Receive the second private key signature sent by the second node; The second private key signature is decrypted based on the second public key to obtain the third digest; and a fourth digest is generated based on the second encrypted information. The process of decrypting the second encrypted information based on the first private key to obtain the business data of the user account when performing target business in M ​​time intervals includes: If the fourth digest is the same as the third digest, the second encrypted information is decrypted based on the first private key to obtain the business data of the user account when performing target business in M ​​time intervals.

5. A method for determining location information, characterized in that, Applied to the second node, the method includes: The system receives first encrypted information sent by the first node and decrypts the first encrypted information based on the second private key to obtain the account identifier of the user account. The second private key is the private key included in the second node. Based on the account identifier of the user account, determine the business data of the user account when performing the target business in M ​​time intervals. The business data includes multiple time intervals and the address of the user account when performing the target business in each of the multiple time intervals. The target business is used to verify the identity of the user account. M is an integer greater than or equal to 1. Based on the first public key, the business data of the user account when performing target business in M ​​time intervals is encrypted to generate second encrypted information, and the second encrypted information is broadcast to the first node and other nodes. The other nodes are at least one node other than the second node, and the first node and the at least one node belong to the same blockchain.

6. The location information determination method according to claim 5, characterized in that, The method further includes: Receive the first private key signature sent by the first node; The first private key signature is decrypted based on the first public key to obtain a first digest; and a second digest is generated based on the first encrypted information. The process of decrypting the first encrypted information based on the second private key to obtain the user account's account identifier includes: If the second digest is the same as the first digest, the first encrypted information is decrypted based on the second private key to obtain the user account's account identifier.

7. The location information determination method according to claim 5, characterized in that, The method further includes: Based on the second encrypted information, a third digest is generated; The third digest is encrypted based on the second private key to generate a second private key signature. The second private key signature is broadcast to the first node and the other nodes.

8. A location information determining device, characterized in that, Applied to the first node, it includes an acquisition module, a processing module, a receiving module, and a determination module; The acquisition module is used to acquire a location determination request. The location determination request includes the user account's account identifier, the mobile subscriber number (MDN) corresponding to the user account, and the location information of the MDN in M ​​time intervals. The location determination request is used to request the determination of the user account's location information, where M is an integer greater than or equal to 1. The processing module is used to encrypt the account identifier of the user account based on the second public key, generate first encrypted information, and broadcast the first encrypted information to at least one node. The second public key is a public key included in the second node, the second node is one of the at least one node, and the first node and the at least one node belong to the same blockchain. The receiving module is used to receive the second encrypted information sent by the second node, and decrypt the second encrypted information based on the first private key to obtain the service data of the user account when performing the target service in the M time intervals. The service data includes multiple time intervals and the address of the user account performing the target service at each of the multiple time intervals. The target service is used to verify the identity of the user account. The first private key is the private key included in the first node. The determining module is used to determine valid location information based on the multiple times and the address of the target service of the user account at each time. The determining module is further configured to determine the location information of the MDN in the M time intervals as the location information of the user account when the location information of the MDN in the M time intervals includes the valid location information.

9. The location information determining device according to claim 8, characterized in that, The plurality of moments includes the first moment. The determining module is specifically used to determine the network device that corresponds to both the first time and the first address. The first address is the address where the user account performs the target service at the first time. The network device is used to provide services to the terminal corresponding to the user account. The determining module is specifically used to determine that the valid location information includes the location information of the network device.

10. The location information determining device according to claim 8, characterized in that, The processing module is further configured to generate a first digest based on the first encrypted information; The processing module is further configured to encrypt the first digest based on the first private key to generate a first private key signature; The processing module is also used to broadcast the first private key signature to the at least one node.

11. The location information determining device according to claim 8, characterized in that, The receiving module is also used to receive the second private key signature sent by the second node; The processing module is further configured to decrypt the signature of the second private key based on the second public key to obtain a third digest; and to generate a fourth digest based on the second encrypted information; The processing module is further configured to, when the fourth digest is the same as the third digest, decrypt the second encrypted information based on the first private key to obtain the business data of the user account when performing target business in M ​​time intervals.

12. A location information determining device, characterized in that, Applied to the second node, it includes a receiving module, a determining module, and a processing module; The receiving module is used to receive the first encrypted information sent by the first node, and decrypt the first encrypted information based on the second private key to obtain the account identifier of the user account. The second private key is the private key included in the second node. The determining module is used to determine the business data of the user account when it performs the target business in M ​​time intervals based on the account identifier of the user account. The business data includes multiple time intervals and the address of the user account when performing the target business in each of the multiple time intervals. The target business is used to verify the identity of the user account. M is an integer greater than or equal to 1. The processing module is used to encrypt the business data of the user account when it performs target business in M ​​time intervals based on the first public key, generate second encrypted information, and broadcast the second encrypted information to the first node and other nodes. The other nodes are at least one node other than the second node, and the first node and the at least one node belong to the same blockchain.

13. The location information determining device according to claim 12, characterized in that, The receiving module is also used to receive the first private key signature sent by the first node; The processing module is further configured to decrypt the signature of the first private key based on the first public key to obtain a first digest; and to generate a second digest based on the first encrypted information; The processing module is specifically used to decrypt the first encrypted information based on the second private key when the second digest is the same as the first digest, so as to obtain the account identifier of the user account.

14. The location information determining device according to claim 12, characterized in that, The processing module is further configured to generate a third digest based on the second encrypted information; The processing module is further configured to encrypt the third digest based on the second private key to generate a second private key signature; The processing module is also used to broadcast the second private key signature to the first node and the other nodes.

15. A server, characterized in that, The server includes: processor; A memory configured to store processor-executable instructions; The processor is configured to execute the instructions to implement the location information determination method as described in any one of claims 1-4, or to implement the location information determination method as described in any one of claims 5-7.

16. A computer-readable storage medium storing instructions thereon, characterized in that, When the instructions in the computer-readable storage medium are executed by the server, the server is able to perform the location information determination method as described in any one of claims 1-4, or the location information determination method as described in any one of claims 5-7.

Citation Information

Patent Citations

  • Account login method and device, equipment and medium

    CN115239261A

  • KR20200093229A